Journal of Software, Vol 5, No 5 (2010), 514-521, May 2010
doi:10.4304/jsw.5.5.514-521

The Formal Model of DBMS Enforcing Multiple Security Polices

Yongzhong He, Zhen Han, Huirong Fu, Guangzhi Qu

Abstract


The formal security policy model and security analysis is necessary to help Database Management System (DBMS) to attain a higher assurance level. In this paper we develop a formal security model for a DBMS enforcing multiple security policies including mandatory multilevel security policy, discretionary access control policy and role based access control policy.  A novel composition scheme of policies is introduced. And the security properties are comprehensively and accurately specified in terms of about 17 state invariants and state transition constraints. Furthermore, the security of the model is proved with the Z/EVES theorem prover.


Keywords


multiple security policies; formal language; security invariant; theorem proving

References



Full Text: PDF


Journal of Software (JSW, ISSN 1796-217X)

Copyright @ 2006-2012 by ACADEMY PUBLISHER – All rights reserved.